Latest CVE Feed
-
9.8
CRITICALCVE-2024-0929
A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been rated as critical. Affected by this issue is the function fromNatStaticSetting. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be lau... Read more
- EPSS Score: %0.18
- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-43135
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /diagnostic/login.php.... Read more
Affected Products : online_diagnostic_lab_management_system- EPSS Score: %0.08
- Published: Nov. 16, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-25078
TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.... Read more
Affected Products : a3600r_firmware- EPSS Score: %5.66
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25095
Home Owners Collection Management System v1.0 allows unauthenticated attackers to compromise user accounts via a crafted POST request.... Read more
Affected Products : home_owners_collection_management_system- EPSS Score: %1.36
- Published: Feb. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-43260
Tenda AC18 V15.03.05.19(6318) was discovered to contain a stack overflow via the time parameter in the fromSetSysTime function.... Read more
- EPSS Score: %0.17
- Published: Oct. 18, 2022
- Modified: May. 12, 2025
-
9.8
CRITICALCVE-2022-43305
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-algorithms package. The affected version of d8s-htm ... Read more
Affected Products : d8s-python- EPSS Score: %0.12
- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2023-36947
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule.... Read more
- EPSS Score: %0.91
- Published: Oct. 16, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25222
Money Transfer Management System Version 1.0 allows an unauthenticated user to inject SQL queries in 'admin/maintenance/manage_branch.php' and 'admin/maintenance/manage_fee.php' via the 'id' parameter.... Read more
Affected Products : money_transfer_management_system- EPSS Score: %2.73
- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-28668
Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.020.23120 has several SQL injection vulnerabilities.... Read more
- EPSS Score: %0.35
- Published: Mar. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25263
JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration.... Read more
Affected Products : teamcity- EPSS Score: %0.02
- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-37152
Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This has been disputed as not a valid vulnerability.... Read more
Affected Products : online_art_gallery- EPSS Score: %0.83
- Published: Jul. 10, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0015
A malicious user with unrestricted access to the AppFormix application management platform may be able to access a Python debug console and execute system commands with root privilege. The AppFormix Agent exposes the debug console on a host where AppFormi... Read more
Affected Products : appformix- EPSS Score: %0.30
- Published: Feb. 22, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-34479
SourceCodester Computer Laboratory Management System 1.0 allows classes/Master.php id SQL Injection.... Read more
Affected Products : computer_laboratory_management_system- Published: Aug. 07, 2024
- Modified: Aug. 08, 2024
-
9.8
CRITICALCVE-2025-25456
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.... Read more
- Published: Apr. 15, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-28242
Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.... Read more
Affected Products :- Published: Apr. 18, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-3458
A vulnerability classified as critical was found in Netentsec NS-ASG Application Security Gateway 6.3. This vulnerability affects unknown code of the file /admin/add_ikev2.php. The manipulation of the argument TunnelId leads to sql injection. The attack c... Read more
- Published: Apr. 08, 2024
- Modified: Feb. 06, 2025
-
9.8
CRITICALCVE-2024-41364
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\trackEdit.php... Read more
Affected Products : phoniebox- Published: Aug. 29, 2024
- Modified: Sep. 04, 2024
-
9.8
CRITICALCVE-2018-0038
Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 have Cassandra service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorized access to information stored in Cassandra.... Read more
Affected Products : contrail_service_orchestration- EPSS Score: %0.49
- Published: Jul. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10423
A vulnerability, which was classified as critical, was found in Project Worlds Student Project Allocation System 1.0. Affected is an unknown function of the file /student/project_selection/project_selection.php of the component Project Selection Page. The... Read more
- Published: Oct. 27, 2024
- Modified: Oct. 29, 2024
-
9.8
CRITICALCVE-2024-35661
Missing Authorization vulnerability in SoftLab Upload Fields for WPForms.This issue affects Upload Fields for WPForms: from n/a through 1.0.2.... Read more
Affected Products : upload_fields_for_wpforms- Published: Jun. 09, 2024
- Modified: Nov. 21, 2024